CVE-2026-8185Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative Interface. Such manipulation leads to missing authentication. The attack requires being on the local network. You should upgrade the affected component. The vendor replied: "We have successfully confirmed and reproduced the issue. We take this matter very seriously and have incorporated the fix into our development schedule. The issue is scheduled to be resolved in the release version coming in late April."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-09); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-09: 3Mentions · 2026-05-11: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-11: 105-0905-11
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-093
Disclosure2General1
2026-05-111
General1
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-8185 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-8185 #CVE-2026-8185 #CVE #Medium #CyberSecurity #InfoSec https://t.co/aankVSjzlz

    Post summary

    A new CVE-2026-8185 is announced with moderate severity, but no specific technical or exploit details are disclosed.

    0000030
    158 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🔐 UGREEN CM933 suffers from missing authentication in admin interface, allowing local network attackers to gain access. #CVE #AuthBypass #Security https://nvd.nist.gov/vuln/detail/CVE-2026-8185

    Post summary

    The tweet reports a missing authentication flaw in the UGREEN CM933 admin interface that could allow local network attackers to gain unauthorized access.

    0000032
    1.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8185 A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative Interface. Such mani… https://www.cve.org/CVERecord?id=CVE-2026-8185

    Post summary

    The post is a brief CVE notice stating a detection in a device, with no evidence of PoC, exploit, active use, patches, detailed technical info, or debunking.

    0000052
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8185 Authentication Bypass in UGREEN CM933 1.1.59.4319 Administrative Interface https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8185

    Post summary

    The post announces CVE-2026-8185, an authentication bypass flaw in UGREEN CM933 firmware, without providing PoC, exploit code, or patch details.

    0000048
    4.0K followersView on X

Explore more